On the night of August 8, hackers exploited a vulnerability in the BTCPay payment server to siphon funds from Lightning Network nodes. Developers confirmed the theft and urged users of the LND software to promptly upgrade to version 2.4.2 or disable their servers.

There is a critical vulnerability being actively exploited on BTCPay Server, which can result in the loss of funds.

Please update your BTCPayServer to 2.4.2 by going to Admin Dashboard -> Server -> Maintenance -> Update & verify the 2.4.2 version string in the footer.

If you…

— BTCPay Server (@BtcpayServer) August 7, 2026

BTCPay allows merchants to accept Bitcoin directly without intermediaries and connects to the Lightning Network for small transactions. Access to the node is managed through .macaroon files, which could be remotely accessed due to a bug, granting attackers total control over the node, enabling them to close channels and withdraw funds.

According to the developers, the vulnerability is limited to configurations using LND, which is the most popular software for Lightning nodes. Regular BTCPay Bitcoin wallets, including hot wallets, are unaffected, but coins stored at LND addresses are at risk due to the compromised node.

The project has not disclosed how many stores were affected or the total amount lost, but they promised a complete incident analysis in the coming days.

The issue was discovered during an AI-assisted audit. The Bitcoin Red Team, a volunteer organization, had previously alerted about the problem. In early August, the group began a comprehensive review of Bitcoin project codebases, utilizing neural networks to produce thousands of reports.

Among the Victims is Wallet Manufacturer Foundation

At least two organizations publicly reported losses. Zach Herbert, CEO of hardware wallet manufacturer Foundation, stated that their Lightning node on BTCPay was drained overnight by attackers, although their on-chain wallet remained unharmed.

How many BTCPay lightning nodes were swept? Our Foundation node was drained overnight by attackers. https://t.co/nt5OFBXB4j

— Zach Herbert 🇺🇸 (@zherbert) August 7, 2026

A similar breach of a node was confirmed by the Bitcoin publication Citadel21, which is managed by a commentator known as hodlonaut. He mentioned that only small amounts were stored on the node.

This is an ongoing attack on BTCPayserver users.

Citadel21's lightning node was just swept. Fortunately there were not much funds there, due to cautionary steps before BIP-110 activation.

Praying for all other affected users. https://t.co/YhdHhoPncH pic.twitter.com/4iRj1HJptL

— hodlonaut #BIP-110 (@hodlonaut) August 7, 2026

It is worth noting that on the night of July 31, approximately 500 owners of Coldcard hardware wallets had 594.48 BTC (around $38.2 million) stolen from them.